VYPR
Unrated severityCISA KEVNVD Advisory· Published Jun 9, 2020· Updated Oct 21, 2025

CVE-2020-13965

CVE-2020-13965

Description

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

Affected products

1
  • Roundcube/Roundcube Webmaildescription

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.